diff options
| author | Kyren223 <Kyren223@proton.me> | 2025-01-07 19:02:14 +0200 |
|---|---|---|
| committer | Kyren223 <Kyren223@proton.me> | 2025-01-07 19:02:14 +0200 |
| commit | 4e2ca64319f17867ac63a8d1283a67e2f1c4daba (patch) | |
| tree | b4f2f1157dd5b590e33018f9e527ce767c0ed95e /internal/client | |
| parent | 4c2672b4970613f9db072231ed4ac07845e431d7 (diff) | |
Fixed all high and medium security issues from gosec
Diffstat (limited to 'internal/client')
| -rw-r--r-- | internal/client/client.go | 2 | ||||
| -rw-r--r-- | internal/client/config/config.go | 6 | ||||
| -rw-r--r-- | internal/client/gateway/gateway.go | 3 | ||||
| -rw-r--r-- | internal/client/ui/auth/auth.go | 6 |
4 files changed, 9 insertions, 8 deletions
diff --git a/internal/client/client.go b/internal/client/client.go index c5fc8a9..5fe2454 100644 --- a/internal/client/client.go +++ b/internal/client/client.go @@ -30,7 +30,7 @@ func Run() { var dump *os.File if ui.DEBUG { var err error - dump, err = os.OpenFile("messages.log", os.O_CREATE|os.O_TRUNC|os.O_WRONLY, 0o644) + dump, err = os.OpenFile("messages.log", os.O_CREATE|os.O_TRUNC|os.O_WRONLY, 0o600) if err != nil { os.Exit(1) } diff --git a/internal/client/config/config.go b/internal/client/config/config.go index ce5a62a..daa3d58 100644 --- a/internal/client/config/config.go +++ b/internal/client/config/config.go @@ -40,13 +40,13 @@ func Load() error { } Dir = filepath.Join(userConfigDir, "eko") - err = os.MkdirAll(Dir, 0o755) + err = os.MkdirAll(Dir, 0o750) if err != nil { return err } ConfigFile = filepath.Join(Dir, "config.json") - contents, err := os.ReadFile(ConfigFile) + contents, err := os.ReadFile(ConfigFile) // #nosec 304 if errors.Is(err, os.ErrNotExist) { config = Default() return write() @@ -98,7 +98,7 @@ func write() error { if err != nil { return err } - return os.WriteFile(ConfigFile, b, 0o644) + return os.WriteFile(ConfigFile, b, 0o600) } func Read() Config { diff --git a/internal/client/gateway/gateway.go b/internal/client/gateway/gateway.go index 9709968..df1503f 100644 --- a/internal/client/gateway/gateway.go +++ b/internal/client/gateway/gateway.go @@ -46,6 +46,7 @@ func init() { tlsConfig = &tls.Config{ RootCAs: certPool, ServerName: "localhost", + MinVersion: tls.VersionTLS12, } } @@ -145,7 +146,7 @@ func handleAuth(ctx context.Context, conn net.Conn, privKey ed25519.PrivateKey) } bytesRead += n } - id := snowflake.ID(binary.BigEndian.Uint64(idBytes[:])) + id := snowflake.ID(binary.BigEndian.Uint64(idBytes[:])) // #nosec G115 return id, nil } diff --git a/internal/client/ui/auth/auth.go b/internal/client/ui/auth/auth.go index d4c4d2f..5e44962 100644 --- a/internal/client/ui/auth/auth.go +++ b/internal/client/ui/auth/auth.go @@ -427,13 +427,13 @@ func (m *Model) Signup() tea.Cmd { } privateKeyFilepath := expandPath(m.fields[privateKeyField].Input.Value()) - err := os.MkdirAll(filepath.Dir(privateKeyFilepath), 0o755) + err := os.MkdirAll(filepath.Dir(privateKeyFilepath), 0o750) if err != nil { m.fields[privateKeyField].Input.Err = errors.Unwrap(err) assert.NotNil(errors.Unwrap(err), "there should always be an error to unwrap", "err", err) return nil } - file, err := os.OpenFile(privateKeyFilepath, os.O_WRONLY|os.O_CREATE|os.O_EXCL, 0o600) + file, err := os.OpenFile(privateKeyFilepath, os.O_WRONLY|os.O_CREATE|os.O_EXCL, 0o600) // #nosec 304 if errors.Is(err, os.ErrExist) { info, e := os.Stat(privateKeyFilepath) assert.NoError(e, "if file exists it should be fine to stat it") @@ -485,7 +485,7 @@ func (m *Model) Signup() tea.Cmd { func (m *Model) signin() tea.Cmd { privateKeyFilepath := expandPath(m.fields[privateKeyField].Input.Value()) - file, err := os.ReadFile(privateKeyFilepath) + file, err := os.ReadFile(privateKeyFilepath) // #nosec 304 if errors.Is(err, os.ErrNotExist) { content := fmt.Sprintf("File '%s' doesn't exist.\nDo you want to sign-up instead?", privateKeyFilepath) m.popup = createPopup(content, []string{"sign-up"}, []string{"cancel"}) |
